The rail determines the shape of fraud
A payment instrument's direction of flow refers to which party initiates the movement of funds: the payee or the payer. This distinction divides instruments into two families, each with its own form of fraud. A pull instrument, such as a card or a direct debit, authorizes the payee to draw funds using a credential held by the payer. The fraud consists of obtaining that credential and reusing it. The victim can still dispute the payment afterward. A push instrument, such as a credit transfer or an instant payment, requires the payer to issue the payment order personally, and the fraud consists of getting the payer to issue it. No bank credential is stolen.
Moving from one family to the other changes the problem that fraud prevention has to solve. On a pull rail, the problem remains technical: authenticate the cardholder, detect the compromised credential, handle the dispute. On a push rail, it becomes human, and the window for correction closes within seconds. The funds belong to the payee as soon as the payment settles. There is no chargeback. The only recourse is a recovery mechanism built from scratch by the regulator or the industry, and whether one exists varies from country to country.
| Rail | Dominant fraud type | Reversibility | Industry-wide countermeasure | Who bears the loss by default |
|---|---|---|---|---|
| Card (pull) | Credential theft, reused in card-not-present sales | Chargeback, within the time limits set by network rules | Strong authentication where the law requires it, tokenization, risk scoring | Issuer or merchant, depending on the liability shift |
| Direct debit (pull) | Misused mandate, unauthorized debit | Refund at the debtor's request, within the scheme's time limit | Mandate checks, lists of authorized creditors | The creditor, through reversal of the debit |
| Instant payment (push) | Payer manipulation, fake payee | None: the payment is final at settlement | Payee verification before sending, limits, payment delays | The payer, unless a dedicated reimbursement regime applies |
| Account-based wallet (push) | Account takeover, then outbound transfer | None on the resulting transfer | Secure enrollment, device change detection | The payer, unless the provider is proven at fault |
Europe: card-not-present sales account for most card fraud
The second Payment Services Directive (PSD2) requires every payment service provider in the European Economic Area to report the fraud it detects. The European Banking Authority (EBA) and the ECB aggregate these reports and publish them by half-year; the latest edition, released December 15, 2025, covers 2024. No other region collects payment fraud data under a regulatory reporting mandate with comparable coverage.
Card-not-present (CNP) payments are card payments initiated without the card being physically presented to the merchant. In the European Economic Area, they account for 28% of card transaction value and 18% of card transaction volume, yet they carry 83% of card fraud, by value and by volume. Relative to the amounts processed, the fraud rate on the remote channel reaches 0.091%, versus 0.007% for card-present payments. That is 13 times higher by value, and 22 times higher by number of transactions.
| Segment | Share of payments (value) | Share of fraud (value) | Fraud rate |
|---|---|---|---|
| Card-present | 72 % | 17 % | 0,007 % |
| Card-not-present | 28 % | 83 % | 0,091 % |
| Cross-border, all counterparties | 18% to 27%, depending on the period | about 70% of card fraud | more than seven times the domestic rate |
| Cross-border, counterparty outside the EEA | – | 30% of card fraud | 17 times the domestic rate |
Strong customer authentication (SCA) combines at least two independent factors from the categories of knowledge, possession, and inherence. Its coverage varies widely by instrument. In 2024, it applied to about 77% of the value of electronic credit transfers, but to only 40% of the number of electronic card payments and 38% of e-money transactions (EBA / ECB, 2024 data). In-person contactless payments explain most of the gap, because the low-value and cumulative-limit exemptions apply to them constantly. By transaction count, most European card payments are therefore still made without strong authentication.
The fraud rate on European credit transfers remains very low. The amount lost to fraud, however, is growing fast: it reached €2.5 billion in 2024, up 16% from 2023. Its makeup changed over the same period. Payer manipulation rose from 65% to 74% of the value of credit transfer fraud between 2023 and 2024, and from 55% to 71% of its volume. Most of the value lost to credit transfer fraud now comes from payment orders that payers issued themselves, under manipulation.
UK: APP fraud and the world's only mandatory reimbursement regime
The UK has run an instant payment rail, the Faster Payments Service, since 2008. It is a Pay.UK scheme, with Vocalink as the technical operator. The rail predates the euro area's instant payment sending mandate by 17 years, so the UK has had that whole period to observe the fraud that comes with it. Authorized push payment (APP) fraud is a payment that the payer makes after being deceived. The UK named it, measured it, and regulated it before any other market.
The Financial Services and Markets Act 2023 required the Payment Systems Regulator (PSR) to introduce reimbursement for victims. Section 71(2) defines a qualifying case as a payment order executed over Faster Payments as a result of fraud or dishonesty. The regulator implemented the requirement through a Specific Requirement addressed to Pay.UK and three Specific Directions, one of which extends the regime to CHAPS. It covers payments executed on or after October 7, 2024. Reimbursement is therefore a legal obligation enforceable against each provider in scope, not a voluntary industry commitment.
| Parameter | Rule | What it requires of the provider |
|---|---|---|
| Scope | Faster Payments and CHAPS, between two UK accounts, including payments initiated through a PIS provider | No other payment system is in scope |
| Cap | £85,000 per claim | Set aside provisions and document the policy applied above the cap |
| Cost sharing | 50/50 between the payer's provider and the payee's provider | Receiving funds puts a price on the quality of your onboarding |
| Excess | Optional, £100 maximum, cannot be applied to vulnerable customers | The split is always calculated as if the excess had been applied |
| Deadline | Five business days, or up to 35 if more information is requested | Investigate, decide, and give written reasons within the deadline |
| Time limit | 13 months after the last payment in the claim | Keep fraud data for the full required period |
| Who is covered | Consumers, microenterprises, and charities | Scope modeled on that of the Financial Ombudsman Service |
| Out of scope | Cards, international payments, other payment systems, civil disputes | A customer whose goods never arrived from a legitimate seller is not an APP victim |
Before reimbursement comes into play, the industry-wide countermeasure is Confirmation of Payee. Run by Pay.UK, it compares the name the payer enters with the name on the destination account, before the transfer is executed. The regulator imposed it on the six largest banking groups through Specific Direction 10, with a deadline of March 31, 2020. Specific Direction 17 extended it to around 400 more providers, with deadlines of October 31, 2023, and October 31, 2024. Five years of operation have revealed four recurring problems: trading names that differ from the legal name, joint accounts, accounts held on behalf of third parties, and false positives that erode payer vigilance.
Brazil: Pix, irrevocability, and a recovery mechanism added after launch
Pix is Brazil's instant payment system, run by the Banco Central do Brasil (BCB) on the SPI infrastructure since November 2020. In five years, it has become the country's leading retail payment method. The rail processed 79.8 billion transactions worth R$35.36 trillion in 2025, and accounted for 54.7% of retail transactions in the second half of 2025 (BCB). A Pix payment is irrevocable once it settles. The rail had no dispute procedure at launch, so consumer protection was built after it went live.
The Mecanismo Especial de Devolução (MED), or special return mechanism, is the recovery procedure imposed on all Pix participants since 2021. The victim contacts their own bank, which has the funds still held by the recipient blocked and then returned. The Banco Central do Brasil publishes every deadline in the procedure: claims can be filed up to 80 days after the payment, analysis takes 7 days, the return request 72 hours, and execution 6 hours (Guia MED, Banco Central do Brasil). Funds that had already left the receiving account were beyond the reach of the original mechanism.
The main vector for Pix fraud remains social engineering aimed at the payer: fake sellers, altered QR codes, fake customer service, physical coercion. MED 2.0 addresses the most common workaround, which is moving funds immediately to a second and then a third mule account. Precautionary blocking now follows that chain. An institution that receives disputed funds therefore faces blocks on its own account, and the quality of its sub-merchant onboarding becomes part of its financial risk.
- Separate MED claims from commercial refund requests from the first contact: they differ in deadlines, point of contact, and outcome.
- Track the MED claim rate by sub-merchant: that metric triggers blocking, not revenue.
- Document the onboarding of every receiving account: an unidentifiable recipient exposes the institution to fund returns and penalties.
- Never promise reversibility in a checkout flow paid with Pix: the rail offers none, and the promise creates a legally false expectation.
India: UPI, AePS, and friction as public policy
Unified Payments Interface (UPI) is India's retail instant payment infrastructure, run since 2016 by the National Payments Corporation of India (NPCI) under a mandate from the Reserve Bank of India. The rail processed 241.62 billion transactions worth ₹314 lakh crore in fiscal 2025-26 (NPCI). Merchant payments on UPI are free for most volumes. Zero fees, instant execution, addressing by virtual ID, and openness to third-party apps all widen the rail's attack surface. The fraud consists of getting the account holder to authorize a payment, with no need to steal any bank credential.
The Aadhaar Enabled Payment System (AePS), run by the NPCI since 2011, supports cash withdrawals, deposits, balance inquiries, and payments by fingerprint at a banking correspondent, with no card or phone needed. The rail underpins financial inclusion in rural India. It is also the country's best-documented fraud vector: identity theft, biometric harvesting, and fraud by the touchpoint operator itself. That last risk stems from the operator's position: the operator enters the customer's Aadhaar number and captures their fingerprint during the transaction.
On June 27, 2025, the RBI issued the directions Aadhaar Enabled Payment System – Due Diligence of AePS Touchpoint Operators (RBI/2025-26/63), in force since January 1, 2026. They require acquiring banks to carry out full due diligence on every touchpoint operator: Aadhaar, PAN (India's tax ID) or an equivalent document, and business details. Banks must also monitor transactions continuously and apply risk-based controls (location profiling, velocity limits). The directions apply to all commercial banks, regional rural banks, and cooperative banks, as well as to the NPCI itself.
The same shift is under way elsewhere in Asia. Since December 16, 2024, Singapore has applied a Shared Responsibility Framework issued by the MAS and the IMDA. Losses from phishing scams are shared among the financial institution, the telecom operator, and the consumer. Compensation is due only if one of the first two breached a duty assigned to it. A deceived consumer therefore bears the loss unless a breach is proven. Hong Kong hit the same problem as early as 2018: a few weeks after the Faster Payment System launched, the HKMA suspended wallet top-ups while the flaws it had found were fixed. PromptPay in Thailand, QRIS in Indonesia, DuitNow in Malaysia, and PayNow in Singapore all raise the same question of who bears the loss, and each market has answered it differently.
US: no strong authentication, and liability rules that vary by instrument
The US has no strong authentication requirement for payers. Federal law has no equivalent of PSD2, so there are no exemptions to document and no fraud-rate threshold to stay under to keep the right to skip authentication. Using 3-D Secure is a business decision, made transaction by transaction. In Europe, the operational goal is to minimize the number of challenges the regulation imposes. In the US, it is to determine when triggering a challenge is justified.
US federal consumer protection rests on two separate regimes, and which one applies depends on the payment instrument. Regulation Z covers credit cards, while Regulation E (12 CFR 1005) covers debit cards and electronic fund transfers. The cardholder's liability depends on how quickly the loss is reported: $50 within two business days, $500 after that. There is no cap at all on transactions that appear on a statement and are reported more than 60 days after it was sent. Network rules sit on top of both regimes and allocate losses among financial institutions. The merchant has no rights of its own under them: it remains a third party to the relationship between the cardholder and their bank.
| Instrument | Applicable regime | Unauthorized transaction | Transaction authorized under manipulation |
|---|---|---|---|
| Credit card | Regulation Z | Cardholder liability capped at $50 | Out of scope; recourse limited to network rules |
| Debit cards and electronic fund transfers | Regulation E (12 CFR 1005) | $50 within two business days, $500 after that, unlimited after 60 days | Out of scope: the customer authorized the transaction |
| Zelle, RTP, FedNow (push credit) | Regulation E, for unauthorized transfers only | Same schedule | No dedicated federal protection to date |
| ACH | Nacha rules, supplemented by Regulation E for consumers | Return windows by SEC code | No automatic reversal |
US law has not settled who bears the loss when a customer personally authorizes a transaction under manipulation. In December 2024, the CFPB sued Early Warning Services and three of its bank owners, seeking reimbursement for this kind of induced fraud on Zelle. The network handled 4.2 billion transactions worth more than $1.2 trillion in 2025 (Early Warning Services, February 2026). The CFPB dropped the case on March 4, 2025, with prejudice. The New York State Attorney General took up the case on August 13, 2025, in New York state court. With the federal regulator out, the question now rests with the states, and the applicable rule depends on where the case is brought.
Fraud rates compared, and what they leave out
A fraud rate divides a fraudulent amount or number of transactions by a reference base, and its value depends as much on the numerator as on that base. Comparing two national rates requires three things to line up, and they rarely do. First, scope. European reporting covers every payment service provider by law, while US statistics include only what victims reported to the FBI. Second, the denominator: a rate may be calculated on value, on volume, or only on transactions by domestic issuers. Third, the triggering event. Some figures count net losses, others gross losses, and others blocked attempts.
| Scope | Published indicator | Value | What the figure leaves out |
|---|---|---|---|
| European Economic Area | Fraud reported by providers under PSD2, 2024 | €4.2 billion, including €2.5 billion in credit transfers and €1.3 billion in cards (EBA / ECB, 2025) | Blocked attempts; fraud the victim never reported to their provider |
| European Economic Area | Card fraud rate, 2024 | 0.033% of value; 0.091% for card-not-present (EBA / ECB, 2025) | Cards issued outside the EEA and used in Europe |
| United Kingdom | Payment fraud losses, 2025 | £1.28 billion, including £576.4 million in APP fraud (UK Finance, 2026) | Fraud suffered outside the reporting members |
| United States | Complaints received by IC3, 2025 | $20.877 billion from 1,008,597 complaints (FBI, 2025) | Anything not reported to the FBI: this is a complaint database, not a market measure |
| Global, cards | Payment card fraud losses, 2024 | $33.4 billion, down 1.2% (Nilson Report, January 2026) | Non-card instruments, including all manipulation fraud on credit transfers |
| Australia | Card-not-present share of card fraud | Nearly 85% of fraud on Australian cards (Australian Payments Network) | Non-card instruments; the country has no general strong authentication requirement |
- Who reports, and under what obligation? A regulated report and a voluntary complaint are never comparable.
- Which denominator? Value or volume: the ratio between the two varies by a factor of two to three depending on the instrument.
- What triggers the count? Net loss after recovery, gross loss, or blocked attempt? Three figures for the same event.
- Which year, and which publication date? Fraud data comes out 12 to 18 months after the fact; a figure presented as recent often describes the year before last.
What an operator has to manage, market by market
An enforceable threshold is a level above which a third party, whether a card network or a regulator, takes action against the party being measured. Two kinds of thresholds coexist. Card network thresholds penalize the merchant and apply wherever cards are accepted, with values that vary by region. Regulatory thresholds penalize the payment provider and change from country to country, so no single policy can work for an operator active in several markets.
| Program | Calculation | Threshold | Consequence |
|---|---|---|---|
| Visa VAMP | (TC40 fraud + TC15 disputes) / TC05 settled transactions | “Excessive” merchant threshold lowered from 2.2% to 1.5% on April 1, 2026, in Europe, the US, Canada, and Asia-Pacific; 2.2% retained in CEMEA | Notification, remediation plan, fees on excess transactions |
| Mastercard ECM | chargebacks in the month / transactions in the previous month | At least 100 chargebacks and a ratio of at least 1.5% | Notification, remediation plan, fines that escalate the longer the merchant stays in the program |
| Mastercard HECM | same calculation | At least 300 chargebacks and a ratio of at least 3% | Higher fines, pressure from the acquirer, risk of termination |
Regulatory obligations differ by market. The same payment journey launched in six countries falls under six liability regimes and six sets of mandatory controls. The list below sums up, market by market, what to work through before opening a payment channel.
- EEA: strong authentication by default, with exemptions to document; the transaction risk analysis exemption is lost if the requesting provider's fraud rate exceeds 0.13%, 0.06%, or 0.01%, depending on the value band (PSD2 RTS). Verification of Payee mandatory on all credit transfers since October 9, 2025.
- UK: mandatory reimbursement of APP victims on Faster Payments and CHAPS, split 50/50, capped at £85,000, within five business days. Confirmation of Payee mandatory for around 400 providers.
- Brazil: MED mandatory for every Pix participant, with blocking extended along the chain of recipient accounts since MED 2.0.
- India: mandatory due diligence on AePS touchpoint operators since January 1, 2026; ₹5,000 limit during the first 24 hours of a new UPI ID.
- US: no authentication requirement; Nacha credit-push fraud monitoring required from March 20 and then June 19, 2026.
- Singapore: anti-scam duties assigned to financial institutions and telecom operators, with compensation due only if a duty is breached (MAS and IMDA, since December 16, 2024).
- Australia: no general strong authentication requirement; the Australian Payments Network framework applies only to merchants exceeding A$50,000 in losses and a 0.2% fraud rate for two consecutive quarters.